curl -X PATCH "https://api.fitsociety.io/public/v1/workout/plans/training-sections-visibility" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({clientId: '67f1234567890abcdef9999'})
};
fetch('https://api.fitsociety.io/public/v1/workout/plans/training-sections-visibility', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/plans/training-sections-visibility"
payload = { "clientId": "67f1234567890abcdef9999" }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)Update a client's training-section visibility toggles
Coach-only. Partially updates the trainingSectionsAccess flags for a specific client. Only the keys present in the request body are changed — omitted keys remain unchanged. All provided section values must be boolean. The client is verified to belong to the coach’s company via connectedCompanies.
Requires the workout_settings:write scope. This operation maps to /app/v1/workout/plans/training-sections-visibility and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter is resolved inside the company bound to the Public API token when present.
curl -X PATCH "https://api.fitsociety.io/public/v1/workout/plans/training-sections-visibility" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({clientId: '67f1234567890abcdef9999'})
};
fetch('https://api.fitsociety.io/public/v1/workout/plans/training-sections-visibility', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/plans/training-sections-visibility"
payload = { "clientId": "67f1234567890abcdef9999" }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Body
The client whose settings are being updated.
"67f1234567890abcdef1234"
Master toggle — disables the entire training page when false.
true
Assigned Plans section (Training Plans group).
true
Freestyle Workout section (Workout Tools group).
true
Video Library section (Workout Tools group).
true
Performance Summary section (Analytics & Data group).
true
Muscle Activation Map section (Analytics & Data group).
true
Daily Notes section (Analytics & Data group).
true
Training Plan Library section (Library group).
true